:

24,000 EXPOSED SERVERS LEAK PASSWORD HASHES VIA 20-YEAR-OLD BMC FLAW

INDUSTRY DESK1 MIN READ
TUE, JUL 28, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Over 24,000 internet-exposed servers are leaking authentication password hashes through a two-decade-old vulnerability in their Baseboard Management Controller (BMC) interfaces. The flaw allows attackers to extract credentials remotely without authentication.

Baseboard Management Controllers are out-of-band management interfaces that let administrators access servers remotely, even when the main operating system is offline. The vulnerability affects multiple BMC implementations and has persisted unpatched for approximately 20 years. Exposed BMC interfaces are particularly dangerous because they operate independently of standard server security measures. Attackers scanning for vulnerable devices can extract password hashes and potentially crack them to gain administrative access to critical infrastructure. The widespread exposure suggests many organizations have failed to restrict BMC access to trusted networks or change default credentials. Security researchers recommend immediately inventorying BMC devices, restricting network access to administrative ranges only, and applying available patches. Organizations should treat BMC security as critical infrastructure protection rather than an afterthought, given attackers' ability to bypass standard server defenses through these interfaces.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A security researcher has developed an algorithm that generates computer-generated patterns capable of evading detection by surveillance cameras. The technique can hide people, faces, and vehicles from AI-powered monitoring systems.

2H AGOSecurity Desk

Scammers are enrolling fake students at US community colleges, using artificial intelligence to complete coursework, and collecting financial aid payouts. The scheme exploits gaps in enrollment verification and assignment monitoring.

3H AGOAI Desk

The Head Mare hacktivist group has compromised TrueConf video conferencing servers and replaced legitimate client installers with trojaned versions containing backdoors.

8H AGOSecurity Desk

OpenAI inadvertently launched a denial-of-service attack against Hugging Face, the popular machine learning platform. The incident has prompted questions about AI infrastructure security and unintended consequences of large-scale operations.

YESTERDAYAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.